Malware

Zusy.305218 removal instruction

Malware Removal

The Zusy.305218 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.305218 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • A file with an unusual extension was attempted to be loaded as a DLL.
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Zusy.305218?


File Info:

name: 481DE74425EE2DFE3DC8.mlw
path: /opt/CAPEv2/storage/binaries/014b422e6c1bc23db2b5898dd0c49ac61fbac174c1e0d916f68b41cfb535cdb5
crc32: D74F76CF
md5: 481de74425ee2dfe3dc8c77e2ad1a3b2
sha1: 9412761e8da84904c5f08e7020a40bf6bc59700f
sha256: 014b422e6c1bc23db2b5898dd0c49ac61fbac174c1e0d916f68b41cfb535cdb5
sha512: 4eb7fcded9d6745c315e5f683c8eae9c5fb942e2fa53f3b96bffa6d690a1755a52ff216a8ea048fa63ba438b44bf8ddbd38186e9148ab7450250e99e63a7b889
ssdeep: 3072:kTlccpug9oWl3lo3wvoC+a6u8KpjCUUKI9joN9pOxheLuvj:k2c3l1uw5P8I3UKFvEx8L
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F5248C0177C284B0D87A02350929AB91553EFCB14FB1536B2799BB9E5EB42C0BF357A3
sha3_384: c86236679eb7d210269aa8bbb1dfc5db3f435044068f481af8eeee50ffb1a6f3c03616e01c24489a2cc279ef55c3d8c4
ep_bytes: e8bb850000e987feffffcc57568b7424
timestamp: 2015-05-20 19:56:42

Version Info:

0: [No Data]

Zusy.305218 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zenpak.4!c
MicroWorld-eScanGen:Variant.Zusy.305218
FireEyeGeneric.mg.481de74425ee2dfe
CAT-QuickHealTrojan.EmotetPMF.S24724929
ALYacTrojan.IcedID.gen
CylanceUnsafe
ZillyaTrojan.IcedId.Win32.2097
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 005637de1 )
AlibabaTrojanDownloader:Win32/Zenpak.cea12054
K7GWTrojan-Downloader ( 005637de1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Zusy.D4A842
VirITTrojan.Win32.IcedID.BB
CyrenW32/Kryptik.BNW.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.IcedId.F
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Zenpak.pef
BitDefenderGen:Variant.Zusy.305218
NANO-AntivirusTrojan.Win32.IcedID.hliuck
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10cdd0f5
Ad-AwareGen:Variant.Zusy.305218
TACHYONBanker/W32.IcedID.220160
ComodoMalware@#1fj169pcbctab
DrWebTrojan.IcedID.27
VIPREGen:Variant.Zusy.305218
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zenpak.bus
WebrootW32.Trojan.Icedid
AviraHEUR/AGEN.1219383
Antiy-AVLTrojan/Generic.ASMalwS.61DD
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Emotet.PPP!MTB
ViRobotTrojan.Win32.S.Downloader.220160.AI
GDataGen:Variant.Zusy.305218
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Trickbot.R338558
McAfeeEmotet-FQS!481DE74425EE
MAXmalware (ai score=100)
RisingSpyware.IcedId!1.C775 (CLASSIC)
YandexTrojan.DL.IcedId!heQ6YVPS+t8
IkarusTrojan-Banker.IcedID
MaxSecureTrojan.Malware.74759756.susgen
FortinetW32/TrickBot.DI!tr
BitDefenderThetaGen:NN.ZexaF.34582.nqW@aWBYjMii
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.425ee2
PandaTrj/Genetic.gen

How to remove Zusy.305218?

Zusy.305218 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment